Latest CVE Feed
-
9.3
HIGHCVE-2005-2619
Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (1) ZIP, (2) UUE or (3) TAR archive that contains a .. (... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2005-3188
Buffer overflow in Nullsoft Winamp 5.094 allows remote attackers to execute arbitrary code via (1) an m3u file containing a long line ending in .wma or (2) a pls file containing a long File1 value ending in .wma, a different vulnerability than CVE-2006-04... Read more
Affected Products : winamp- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3538
hfaxd in HylaFAX 4.2.3, when PAM support is disabled, accepts arbitrary passwords, which allows remote attackers to gain privileges.... Read more
Affected Products : hylafax- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2005-3712
Heap-based buffer overflow in rsync in Mac OS X 10.4 through 10.4.5 allows remote authenticated users to execute arbitrary code via long extended attributes.... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4644
Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.... Read more
Affected Products : trac- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4694
Unspecified vulnerability in the www_add method in Asset.pm in Plain Black WebGUI 6.3.0 and other versions before 6.7.6 allows attackers to execute arbitrary code via unknown attack vectors.... Read more
Affected Products : webgui- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-4837
snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote attackers to cause a denial of service (crash) by causing a particular TCP disconnect, which triggers a fr... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2005-1730
Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonstrated by "OpenSSL ASN.1 brute forcer." NOTE: this issue... Read more
Affected Products : imanager- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2005-1924
The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharacters in (1) the fpr parameter to the deleteKey function in gpg_keyring.php, as called by (a) import_key_file.php, (b... Read more
Affected Products : gpg_plugin- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2462
Kayako liveResponse 2.x, when logging in a user, records the password in plaintext in the URL, which allows local users and possibly remote attackers to gain privileges.... Read more
Affected Products : liveresponse- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-2713
passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to create arbitrary world-writable files as root by specifying an alternate file in the password database option.... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3708
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via crafted TGA image files.... Read more
Affected Products : quicktime- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2005-4796
Unspecified vulnerability in the XView library (libxview.so) in Solaris 2.5 to 10 allows local users to corrupt files via unknown vectors related to the handling of the clipboard selection while an XView application exits.... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4797
Directory traversal vulnerability in printd line printer daemon (lpd) in Solaris 7 through 10 allows remote attackers to delete arbitrary files via ".." sequences in an "Unlink data file" command.... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2005-4835
The ath_rate_sample function in the ath_rate/sample/sample.c sample code in MadWifi before 0.9.3 allows remote attackers to cause a denial of service (failed KASSERT and system crash) by moving a connected system to a location with low signal strength, an... Read more
Affected Products : madwifi- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1726
The CoreGraphics Window Server in Mac OS X 10.4.1 allows local users with console access to gain privileges by "launching commands into root sessions."... Read more
Affected Products : mac_os_x- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3625
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) D... Read more
Affected Products : enterprise_linux debian_linux enterprise_linux_desktop poppler xpdf suse_linux linux xpdf kdegraphics kpdf +26 more products- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-3706
Heap-based buffer overflow in LibSystem in Mac OS X 10.4 through 10.4.5 allows context-dependent attackers to execute arbitrary code by causing an application that uses LibSystem to request a large amount of memory.... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4619
SQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the rollid parameter in the showhtmllist method.... Read more
Affected Products : zorum- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4774
Cross-site scripting (XSS) vulnerability in Xerver 4.17 allows remote attackers to inject arbitrary web script or HTML after a /%00/ sequence at the end of the URI.... Read more
Affected Products : xerver- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025